CVE-2021-47795
MEDIUM EXPLOITEDGeoVision GeoWebServer 5.3.3 - RCE
Title source: llmDescription
GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.
Exploits (1)
Scores
CVSS v3
6.2
EPSS
0.0004
EPSS Percentile
10.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2026-01-25
CWE
CWE-22
Status
published
Products (1)
Geovision/GeoVision Geowebserver
<= 5.3.3
Published
Jan 16, 2026
Tracked Since
Feb 18, 2026